Live data from Hacker News

U.S. national-security leaders included me in a group chat

theatlantic.com

371–380 of 1001 posts

Re: U.S. national-security leaders included me in a group chat

#371
This hypocrisy reminds me of one of my former lead developers. He required everyone on the team to go through multi-person code reviews and pass an extensive CI suite before merging changes into our mainline.

But him? Half that time he'd approve his own changes without review, the other half he would force-push and bypass the CI system entirely.

He knew the system well and seemed to do enough local testing to avoid major breakage but still. Why have a bunch of rules and policies that you do not follow yourself?

Re: U.S. national-security leaders included me in a group chat

#374

Without commenting on the (important) political or reputational considerations here, I want to talk a bit about the operational risk presented by this practice. There is a somewhat sizable "So what? Signal is e2e encrypted. Nothing bad happened and you're all overreacting." narrative floating around. (not so much in this thread, but in the general discourse) If this operation was planned in Signal, then so were count…

It seems one of the people (and thus the phone) was actually in Moscow during the chat!

Re: U.S. national-security leaders included me in a group chat

#375
post #182

How can we know this group chat was really comprised of government officials and not some bored teenagers? Signal allows you to set your profile name to anything you like.

Watch the Senate Intelligence Committee hearing from earlier today. You can hear one of the participants in that chat acknowledge that he's in it and it's real in response to the questions of committee members.

This is not in question, at all.

Re: U.S. national-security leaders included me in a group chat

#376
post #141

Setting aside the obvious shock of the actual subject, I'm going to try the herculean task of bringing this back to being a HN-related topic... My guess is that there is someone named Jeffrey Goldberg in the NatSec team (or high up, it seems like a common combination of first and last name at least), and likely that they meant to add him, rather than the EDITOR IN CHIEF of the Atlantic of all people. Could this be a…

This sounds less like a Signal problem than an information organization problem. Signal can only show what's in its datastore (your contact list).

I just checked on Android - if you try to add someone to a group chat, it shows their name and profile pic.

One potential Signal-side wrinkle is that it allows you to add people to a group chat who are in another chat you're in, but who aren't in your contacts list. There are strangers I was apparently at a dinner party with years ago who are eligible to be added to a group chat. If Jeffrey Goldberg has his Signal profile name set to JG and he wasn't in Mike Waltz's phone with a more specific name, that could lead to this mistake.

Re: U.S. national-security leaders included me in a group chat

#377

Without commenting on the (important) political or reputational considerations here, I want to talk a bit about the operational risk presented by this practice. There is a somewhat sizable "So what? Signal is e2e encrypted. Nothing bad happened and you're all overreacting." narrative floating around. (not so much in this thread, but in the general discourse) If this operation was planned in Signal, then so were count…

Or not even the device: The other reason we have SCIFs is they provide a secure location. These personal devices could have been in use anywhere, including places where they were subject to observation. Including but not limited to Moscow. :)

Re: U.S. national-security leaders included me in a group chat

#378

Earlier quoted context omitted.

Trump's razor: The opposite of what he says is closer to the truth.

Addendum: Anything GOP accuses others of, they're doing.

Someone only looks behind the door if they have stood there themselves.

Re: U.S. national-security leaders included me in a group chat

#380

In the banking world, employees have been fined significant sums, or even forced from their jobs [0], for unauthorized use of messaging platforms. And here, it's barely a shrug. Unbelievable. [0] https://www.reuters.com/business/finance/morgan-stanley-hit-...

it's not unauthorized use of signal; "Government officials have used Signal for organizational correspondence, such as scheduling sensitive meetings, but in the Biden administration, people who had permission to download it on their White House-issued phones were instructed to use the app sparingly, according to a former national security official who served in the administration." https://www.pbs.org/newshour/nation…

Did you read the article? Signal is not approved for this kind of communication and has long been advised against. They also had messages set to autodelete which violates the records act. It's blatantly illegal
Post reply on HN